Organisations using insecure hardware could face action under General Data Protection Regulation (GDPR).
According to privacy and data protection expert, Dr Kuan Hon, many companies are failing to pay enough attention to their GDPR obligations when it comes to maintaining up-to-date firmware in a secure state.
If companies are found to be deploying outdated or vulnerable firmware that subsequently contributes to the breach of personal data they could face stiff penalties from the Information Commissioner Office (ICO). Hon, director of a privacy, security and information group at law firm Fieldsfisher, asserts that GDPR regulations almost certainly extend to hardware choices and their maintenance.
Hon said: “Not checking hardware is secure before procuring it, not configuring it securely (for example, not changing bad default passwords) and not expeditiously patching vulnerabilities in firmware (and other software) used to process personal data.
“All these could well breach the ‘data protection by design and by default’ obligation on controllers – as well as the security obligation on both controllers and, where relevant, data processors (service providers engaged by data controllers to process personal data, such as cloud providers or payroll service providers – who must also keep personal data secure).
“And that could also breach the core data protection principle of ‘integrity and confidentiality’ that binds controllers (and carries a higher-tier fine under the GDPR, unlike the security/data protection by design and by default obligations), as insecure firmware could lead to a breach of integrity, confidentiality – or both.”
Vulnerable Firmware Contravenes GDPR
To put this in context, if a company installs an outdated and insecure version of software on an IoT device they could face fines under GDPR if it is used as an entry point by cyber attackers. So, for example, if the a firm installs a CCTV system that runs an old and insecure version of Linux on their IoT digital video recorders and hackers exploit this, under GDPR obligations they would be liable.
Hon’s comments were made following a joint public statement from the Department for Culture, Media and Sport (DCMS) and the National Cyber Security Centre (NCSC) after their July roundtable, which had Apple, Intel, Qualcomm, Samsung and Microsoft in attendance. The statement read: “All those present highlighted the value of existing industry collaboration in providing stable updates to firmware across a wide range of devices, and under significant time pressure.”






